Security Detection & SIEM Engineer
Gefragte Skills
Stellenbeschreibung
Singapore | SGD5,500–6,500 | Full-time
职位重点: 安全事件调查、检测规则优化、CVE分析及日常SIEM 运维。
职位简介
我们正在招聘一名安全检测与SIEM 工程师,负责支持公司的安全监控及SIEM 环境。该职位主要负责SIEM 运维、安全事件调查与分析、检测优化、CVE分析以及日常安全监控工作。
主要职责
负责日常SIEM 运维及安全监控工作。
负责通过TheHive 对安全告警及事件进行调查与分析,包括证据审查、调查、记录及工单处理。
负责CVE 信息分析及汇整,识别受影响系统及潜在影响,并协调修复跟进及相关记录。
负责安全检测规则及基础关联逻辑的调整、优化及维护,以提升检测效果。
负责安全事件调查及分析,根据调查结果判断是否需要升级处理或关闭工单。
负责对安全调查过程中发现的恶意或可疑命令、日志、脚本及系统行为进行自主查询、验证及分析。
负责安全监控报告、监控指标、仪表板及日常运营总结的编制与维护。
与基础设施及应用团队协作,支持事件处理及持续优化。
任职资格
信息安全、网络安全、计算机科学或相关专业本科及以上学历。
至少3 年 SIEM 运维、安全监控、安全分析或相关安全工程工作经验。
具备SIEM、日志管理或安全监控平台的实际操作经验。
具备扎实的Linux 和Windows 系统管理及安全日志分析能力。
具备使用OpenSearch 进行安全调查的实际经验,包括日志查询、日志分析、安全事件调查及基本索引管理。
具备安全事件调查、事件分析及检测规则优化经验。
具备较强的分析、故障排查及问题解决能力,并注重工作细节。
具备良好的英语及华文沟通能力,能够与区域相关团队进行有效协作。
优先经验
具备TheHive 告警或事件调查经验。
熟悉安全事件关联分析、行为分析及安全检测工程相关概念。
具备CVE 分析及修复跟进经验。
具备Python、Shell 脚本或安全自动化经验。
职位影响
该职位提升安全检测及事件调查的整体效果,支持相关团队及时处理安全事件,并控制不相关的安全告警。
Role focus: Security event investigation, detectiontuning, CVE analysis and day-to-day SIEM operations.
About the Role
Join our security team and help strengthen how we identify, investigate and respond to security threats. You will work hands-on with security alerts, logs, detection rules and vulnerability findings, turning technical evidence into clear and actionable outcomes.
What You’ll Do
Manage daily SIEM operations and security monitoring activities.
Investigate security alerts and cases through TheHive, including evidence review, analysis, documentation and case handling.
Analyse CVE findings, identify affected systems and potential impact, and coordinate remediation tracking and follow-up.
Tune and maintain security detection rules and basic correlation logic to improve detection effectiveness.
Investigate security incidents and determine the appropriate escalation or case closure.
Analyse suspicious commands, logs, scripts and system activities, validating findings before reaching conclusions.
Prepare security monitoring reports, metrics, dashboards and operational summaries.
Work with infrastructure and application teams to support incident handling and continuous improvement.
What We’re Looking For (Must Have)
Bachelor’s degree in Information Security, Cybersecurity, Computer Science or a related field.
At least 3 years of relevant experience in SIEM operations, security monitoring, security analysis or security engineering.
Hands-on experience with SIEM, log management or security monitoring platforms.
Hands-on OpenSearch experience covering log queries, log analysis, security event investigation and basic index management.
Strong knowledge of Linux and Windows administration fundamentals and security log analysis.
Practical experience insecurity event investigation, incident analysis and detection tuning.
Strong analytical, troubleshooting and problem-solving skills, with the ability to investigate unfamiliar technical behaviour independently.
Effective communication in English and Mandarin, as the role works with regional stakeholders who primarily communicate in these languages.
Good to Have
Experience using TheHive for alert or case investigation.
Familiarity with event correlation, behavioural analysis and detection engineering concepts.
Experience in CVE analysis and vulnerability remediation tracking.
Python, Shell scripting or security automation experience.
Why This Role Matters
Your work will directly improve the quality of our security detections and investigations, helping teams respond to genuine threats more quickly and reduce unnecessary alert noise.
Quelle: mycareersfuture.gov.sg. Für die Inhalte der Inserate übernehmen wir keine Haftung.
Bewerbungstext erstellen
Wir erstellen aus deinem Profil und dieser Stelle einen Entwurf. Du prüfst und passt ihn an.
Nur mit Konto verfügbar.
Jetzt anmelden